High severity8.8NVD Advisory· Published Aug 19, 2026· Updated Sep 3, 2026
CVE-2026-76220
CVE-2026-76220
Description
GitPython before 3.1.58 contains a command execution vulnerability in the check_unsafe_options guard that can be bypassed by combining a single-character kwarg with split_single_char_options=False. Attackers can supply a crafted kwargs dictionary to guarded methods like clone_from to emit a joined token parsed as --upload-pack, enabling arbitrary OS command execution at default allow_unsafe_options=False.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
GitPythonPyPI | < 3.1.58 | 3.1.58 |
Affected products
2- Range: <3.1.58
Patches
Vulnerability mechanics
References
7- github.com/gitpython-developers/GitPython/security/advisories/GHSA-wvpp-8hx9-p66jnvdExploitVendor AdvisoryWEB
- github.com/advisories/GHSA-wvpp-8hx9-p66jghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2026-76220ghsaADVISORY
- www.vulncheck.com/advisories/gitpython-before-command-execution-via-split-single-char-optionsnvdThird Party AdvisoryWEB
- github.com/gitpython-developers/GitPython/commit/96a888f4d782cb2f80452148e48e60ce4af6d541ghsaWEB
- github.com/gitpython-developers/GitPython/pull/2204ghsaWEB
- github.com/gitpython-developers/GitPython/releases/tag/3.1.58ghsaWEB
News mentions
1- Gitpython: Six High-Severity Vulnerabilities Patched in Version 3.1.58Vypr Intelligence · Aug 19, 2026